Effective date: [EFFECTIVE DATE] · Last updated: [DATE] · Version: 1.0
⚠️ DRAFT — NOT LEGAL ADVICE. This is a working template for a licensed attorney to review and finalize before publication. It is the publicly-posted written retention schedule and destruction guidelines required by the Illinois Biometric Information Privacy Act (BIPA §15(a)), and is read together with our Biometric Notice & Written Release and Privacy Policy (§6–7). Replace every [BRACKET] before use.
BIPA §15(a) requires any private entity in possession of biometric identifiers or biometric information to develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying that data. This document is that policy. Where this schedule and any other CookCredit document differ on the retention period, this schedule controls.
This schedule governs the biometric data CookCredit collects through the knife-skill capture feature:
while you chop, and the motion derived from them.
trajectories, motion embeddings, and skill features stored against your account.
It does not apply to face data: the pre-test check is liveness/presence detection only, and CookCredit does not create or store a face template / faceprint. See Biometric Notice §2.
CookCredit retains biometric data only as long as needed for the purpose it was collected (scoring your knife skill and training/validating cooking-skill and robotics/AI models — see Biometric Notice §3). Biometric data is permanently destroyed on the earlier of:
it resets each time you use the Services).
This is the outer limit; we destroy sooner where the purpose is met sooner (for example, when you withdraw consent or delete your account).
Best-practice note (for counsel): some leading programs commit to a tighter ceiling (e.g., a fixed 3-year cap and a 2-year cap for Colorado residents). Confirm whether to adopt a shorter outer limit and/or a hard cap measured from first collection in addition to the rolling last-interaction clock.
We initiate destruction when any of the following occurs:
| Trigger | What happens |
|---|---|
| Account deletion | Deleting your account queues your biometric data for destruction. |
| Withdrawal of consent | Withdrawing the biometric release stops new collection/use and queues destruction. |
| Purpose fulfilled | When the scoring/training purpose is complete for your data. |
| 3-year lapse | 3 years after your last interaction, with no earlier trigger. |
| Unlawful/again-required | If we determine we should not hold it (e.g., a state gate change). |
Permanent destruction reaches biometric data wherever it lives, not only the primary database:
cycle, no later than [e.g., 90] days after the destruction trigger;
required to destroy their copies on our instruction within [e.g., 30] days.
Destruction is permanent and irreversible — records are deleted and, where the storage medium supports it, cryptographically erased (destroying the encryption keys so the data cannot be reconstructed). Destruction is wired to account deletion so it cannot be skipped, and each destruction run is logged for audit (the audit log records that destruction occurred and when — it does not retain the biometric data itself).
biometric identifiers and are not reversible** to you; consistent with the forward-only withdrawal terms in the Biometric Notice §6, destruction of your biometric data does not un-train models already trained.
longer biometric data under this schedule and may be retained, provided we do not attempt to re-identify you.
Consistent with BIPA §15(c)–(d) and the Biometric Notice §5, CookCredit does not sell, lease, trade, or otherwise profit from biometric data, and does not disclose it except as needed to provide the Services, where the law requires, or with your consent.
Until the dedicated written release and this schedule are live in a given state, CookCredit does not collect hand-geometry data from residents of Illinois (BIPA), Texas (CUBI), or Washington. This gate is CookCredit's responsibility and is enforced server-side. See Biometric Notice §8.
collect, why, or how long we keep it; the "Last updated" date and version change accordingly.
To withdraw consent, request deletion of your biometric data, or ask a question, use in-app settings or email [PRIVACY EMAIL]. We will verify your identity and act within the time the law requires.
| Version | Date | Change |
|---|---|---|
| 1.0 | [DATE] | Initial publication. |
CookCredit — draft legal documents. This is a beta preview and not legal advice.